• Dave Syer's avatar
    Explicitly disable security on management endpoints if requested · 63a2d067
    Dave Syer authored
    Previously the management endpoint filter was applied to all requests
    if the user had disabled security.management.enabled, but since it
    had no security applied it was letting all requests through.
    
    The fix was to explicitly exclude the whole enclosing configuration
    and carefully ignore the management endpoints in the normal security
    chain.
    
    Fixes gh-100.
    63a2d067
logback.xml 276 Bytes